10

CVSS3.1

CVE-2025-26701 -

An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead to SSH access, use of Sudo to root, and sensitive data exposure. This is fixed in PMM2 2.42.0-1.ova, 2.43.0-1.ova, 2.43.1-1.ova, 2.43.2-1.ova, and 2.44.0-1.ova and in PMM3 3.0.0-…

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-51320 -

Cross Site Scripting vulnerability in Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution via the /servlet/gsdm_fsave_htmltmp, /servlet/gsdm_btlk_openfile components

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 2:50 p.m.

7.1

CVSS3.1

CVE-2025-25749 -

An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: April 7, 2025, 2:06 p.m.

5.4

CVSS3.1

CVE-2025-25747 -

Cross Site Scripting vulnerability in DigitalDruid HotelDruid v.3.0.7 allows an attacker to execute arbitrary code and obtain sensitive information via the ripristina_backup parameter in the crea_backup.php endpoint

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 2:47 p.m.

5.7

CVSS3.1

CVE-2024-58102 -

An issue was discovered in Datalust Seq before 2024.3.13545. An insecure default parsing depth limit allows stack consumption when parsing user-supplied queries containing deeply nested expressions.

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 8:29 p.m.

6.5

CVSS3.1

CVE-2025-27911 -

An issue was discovered in Datalust Seq before 2024.3.13545. Expansion of identifiers in message templates can be used to bypass the system "Event body limit bytes" setting, leading to increased resource consumption. With sufficiently large events, there can be disk space exhaustion (if saved to di…

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 8:25 p.m.

1.8

CVSS3.1

CVE-2025-27893 -

In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. NOTE: the Supplier analyzed the reported exploitati…

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: Aug. 8, 2025, 1:15 p.m.

7.6

CVSS3.1

CVE-2024-51321 -

In Zucchetti Ad Hoc Infinity 2.4, an improper check on the m_cURL parameter allows an attacker to redirect the victim to an attacker-controlled website after the authentication.

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 2:48 p.m.

7.7

CVSS3.1

CVE-2025-25680 -

LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:16 p.m.

5.4

CVSS3.1

CVE-2025-25929 -

A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the reportType parameter.

πŸ“… Published: March 11, 2025, midnight πŸ”„ Last Modified: July 7, 2025, 6:16 p.m.
Total resulsts: 349182
Page 6398 of 34,919
Β« previous page Β» next page
Filters